Australia's anti-money-laundering regime just got a great deal bigger. The Tranche 2 reforms have pulled tens of thousands of professional-services firms — lawyers, accountants, real estate agents and others — into the AML/CTF Act for the first time. Obligations for these newly-captured entities commenced on 1 July 2026, and the AUSTRAC enrolment window for them closed on 29 July 2026. If your firm provides a designated service, you are almost certainly already a reporting entity. This guide explains what changed, whether you're captured, and exactly what you need in place.
On this page
What the Tranche 2 reforms actually are
For most of the last two decades, Australia's Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act) applied mainly to banks, remitters, gaming operators and other financial businesses. A whole class of professions that routinely handle high-value transactions and help move, structure and hold money sat outside it. Internationally these are known as designated non-financial businesses and professions, and the global standard-setter for AML has long expected countries to bring them into the net. In Australia, that expansion is what everyone calls "Tranche 2".
The reforms extend the AML/CTF Act so that when a firm in one of the captured professions provides a specified activity — a designated service — that firm becomes a reporting entity and takes on the same core family of obligations that banks have carried for years. The obligations are scaled to risk, not identical in volume to a major bank's, but the framework is the same: know your customer, understand your money-laundering and terrorism-financing risk, monitor for the unusual, report it, and be able to prove you did all of it.
Who is captured
The reforms target the professions most often used — knowingly or not — to launder proceeds, hide beneficial ownership, or move value through property and high-value goods. In broad terms, the captured groups are:
- Lawyers and conveyancers — legal practitioners and conveyancing firms, particularly where they handle client money, act on property transactions, or set up structures.
- Accountants, bookkeepers and BAS agents — accounting practices and bookkeeping providers that assist with transactions, structures, or the management of client funds.
- Real estate agents and buyers' agents — those acting on the sale, purchase or transfer of real property on behalf of a client.
- Property developers — where their activities fall within the designated services relating to real estate.
- Dealers in precious metals and stones — businesses buying and selling bullion, gold, gemstones and similar high-value goods above the relevant thresholds.
- Trust and company service providers (TCSPs) — firms that form companies or trusts, act as or arrange nominee directors or shareholders, or provide registered-office and related services.
Two things trip firms up here. First, being in one of these industries does not automatically capture you — and not being an obvious "law firm" or "accountant" does not automatically exempt you. What matters is whether you provide a designated service. Second, many firms provide a mix of services, only some of which are designated. The task is to look through your service lines, not just your business card.
What a "designated service" means — and why it makes you a reporting entity
The pivot point of the entire regime is the concept of a designated service. The AML/CTF Act contains a list of specific activities. Provide one of those activities to a customer, and the law treats you as a reporting entity for that service, with obligations attached. It is the activity that triggers coverage, not the label on your firm.
This activity-based test is deliberate. A single practice might offer a dozen services, of which only two or three are designated. A firm that thinks of itself as "just doing conveyancing" may be squarely captured. The practical implication is that the first serious piece of work is a service-line mapping exercise: list what you actually do for clients, and test each activity against the designated-services list. That determination drives everything downstream — enrolment, the scope of your program, which customers need due diligence, and what you monitor.
Because coverage is per-service, it is entirely possible to be a reporting entity for one part of your business and outside the regime for another. Getting this scoping right is not a technicality; it defines the size and shape of your compliance obligation. Our AML/CTF advisory team spends a large part of every Tranche 2 engagement precisely here, because a wrong call at this stage propagates into every later control.
The timeline that matters — and why "already obligated" is the key phrase
There are two firm dates every captured business needs to hold in mind:
- 1 July 2026 — obligations commenced. From this date, Tranche 2 entities that provide a designated service carry AML/CTF obligations under the Act. This is not a warm-up or a voluntary phase; it is the start of live obligation.
- 29 July 2026 — AUSTRAC enrolment closed. The enrolment window for these newly-captured entities has now closed. A firm that provides a designated service and has not enrolled is not "about to be" obligated — it is already obligated, and already behind.
That is the uncomfortable reality this article exists to name plainly: for a large number of firms, the questions are no longer "when will this affect me?" but "am I already exposed, and how fast can I fix it?" If you are reading this and you provide a designated service, treat yourself as obligated today and work backwards to close the gap. We deal with the remediation path in detail below.
The eight things a captured business must have in place
Whatever your profession, the AML/CTF framework asks for the same core set of controls. Here are the eight that a Tranche 2 reporting entity needs to stand up.
1. AUSTRAC enrolment and registration
Every reporting entity must be enrolled with AUSTRAC. Enrolment is the formal step that puts you on the register and connects you to AUSTRAC's reporting channels. With the enrolment window having closed on 29 July 2026, firms that have not yet enrolled should treat this as the single most urgent item — you cannot lodge the reports the Act requires from a business that is not enrolled.
2. An AML/CTF program (Part A and Part B)
Your AML/CTF program is the written backbone of your compliance. It has two halves. Part A sets out your risk-based systems and controls: how you identify, assess, manage and reduce your money-laundering and terrorism-financing risk, plus governance, oversight, the role of your compliance officer, training and independent review. Part B covers customer identification — the procedures you follow to know who your customer is before you provide a designated service. The program must be documented, approved at the right level, and genuinely used, not filed and forgotten.
3. An ML/TF risk assessment
Underneath the program sits a documented money-laundering and terrorism-financing risk assessment. This is where you think through the risk your particular business faces across your customers, the services you provide, the delivery channels you use, and the countries or jurisdictions you touch. The risk assessment is not paperwork for its own sake — it is what makes your program "risk-based". Your controls, your due-diligence intensity and your monitoring should all trace back to what this assessment concludes.
4. KYC, customer due diligence and enhanced due diligence
Before providing a designated service, you must know who you are dealing with. Customer due diligence (CDD) means identifying and verifying your customer — and, where relevant, the beneficial owners behind them and the purpose of the relationship. Where the risk is higher — for example, politically exposed persons, opaque structures, or higher-risk jurisdictions — you must apply enhanced customer due diligence (ECDD), digging deeper and, where appropriate, obtaining senior approval to proceed. Good CDD is also good client practice; it protects the firm as much as it satisfies the regulator.
5. Ongoing transaction monitoring, SMRs and TTRs
Onboarding is not a one-off. You must monitor your customers and their transactions on an ongoing basis, looking for activity that is unusual, inconsistent with what you know about the customer, or otherwise suspicious. Two reporting obligations flow from this:
- Suspicious matter reports (SMRs) — lodged with AUSTRAC when you form a suspicion on reasonable grounds about a matter relevant to money laundering, terrorism financing or certain other offences.
- Threshold transaction reports (TTRs) — lodged for transfers of physical currency (or equivalent) at or above the reporting threshold.
Both require you to have a process for spotting the trigger, making the decision, and lodging the report within the required timeframe — and to keep the customer relationship confidential where the law requires it.
6. An AML/CTF compliance officer
You must appoint a nominated AML/CTF compliance officer — a person at management level with responsibility for the program's day-to-day operation and its oversight. In a small firm this may be a partner or principal wearing an additional hat; the point is that a named, accountable person owns compliance, rather than it being everyone's job and therefore no one's.
7. Staff training and record-keeping
Your people are your first line of detection. Staff who deal with customers or transactions need training appropriate to their role, so they can recognise red flags and know what to do. Alongside training sits record-keeping: you must retain identification records, transaction records and program documentation for the periods the Act requires, so that you can demonstrate compliance if AUSTRAC asks.
8. An independent review of the program
Finally, your AML/CTF program must be subject to independent review — an assessment, conducted by someone independent of the program's day-to-day operation, of whether it is appropriate to your risk and whether it is actually working. This is not a light-touch requirement; a genuine independent review looks for the gaps between what your program says and what your firm does. It is one of the clearest signals to a regulator that you are taking the regime seriously, and it is one of the services we deliver most often. You can read more on our services page.
Your Tranche 2 compliance checklist
The table below turns those eight obligations into a working checklist. Use it to take stock of where your firm stands right now — every row you cannot honestly tick is an open exposure.
| Requirement | What it means | Status to reach |
|---|---|---|
| Scoping | Map your service lines against the designated-services list to confirm whether — and where — you're captured. | Documented determination of which services are designated |
| AUSTRAC enrolment | Register as a reporting entity so you can lodge reports. Window closed 29 July 2026. | Enrolled and on the register |
| AML/CTF program | Written Part A (systems & controls) and Part B (customer identification), approved and in use. | Documented, approved, operational |
| ML/TF risk assessment | Assess risk across customers, services, channels and jurisdictions; drive your controls from it. | Documented and reflected in controls |
| KYC / CDD & ECDD | Identify and verify customers and beneficial owners; apply enhanced diligence to higher-risk cases. | Applied before providing a designated service |
| Monitoring, SMRs & TTRs | Ongoing monitoring, with processes to lodge suspicious matter and threshold transaction reports on time. | Live monitoring and reporting process |
| Compliance officer | A named, management-level person accountable for the program. | Appointed and empowered |
| Training & records | Role-appropriate staff training and retention of identification, transaction and program records. | Delivered and retained to required periods |
| Independent review | An independent assessment of whether the program is appropriate and effective. | Scheduled and conducted independently |
What "already exposed" means — and how remediation works
Because obligations commenced on 1 July 2026 and enrolment closed on 29 July 2026, a firm that provides a designated service and has done nothing is not in a grace period — it is in breach of live obligations. That is worth stating without softening, because the instinct in professional-services firms is often to hope the issue is theoretical. It is not; the exposure is real from the moment you provide a designated service.
The good news is that remediation is a well-worn path, and regulators generally distinguish between a firm that identifies its own gap and moves decisively to close it, and one that ignores the problem. A sensible remediation sequence looks like this:
- Confirm capture. Map your services and determine, on the record, which are designated and from what date you began providing them.
- Enrol without further delay. Get onto the AUSTRAC register so you can meet your reporting obligations.
- Stand up an interim program. Put a workable Part A and Part B in place now, even if it will be refined — an operating program beats a perfect draft.
- Document your risk assessment. Capture your ML/TF risk so your controls are demonstrably risk-based.
- Start due diligence and monitoring. Apply CDD to current designated-service customers and begin monitoring, with a process ready for SMRs and TTRs.
- Record everything. Keep a clear, dated trail of your remediation decisions and actions — it is evidence of good faith.
- Book the independent review. Schedule an independent look at what you've built so gaps are found by you, not by the regulator.
What to do this month
If you take nothing else from this guide, take these five moves and start them now:
- Decide, in writing, whether you're captured. Map your services against the designated-services list. If any service is designated, you are a reporting entity for it.
- Enrol with AUSTRAC. The window has closed, which makes this more urgent, not less. You cannot report from an un-enrolled business.
- Stand up a working AML/CTF program and risk assessment. Get Part A, Part B and a documented ML/TF risk assessment operating — interim is fine, absent is not.
- Name your compliance officer and train your people. Put an accountable person in place and make sure client-facing staff can spot and escalate red flags.
- Get an independent set of eyes on it. An independent review will tell you where the real gaps are before anyone else does.
None of this needs to be done alone, and it does not need to grind your practice to a halt. The obligations are scaled to your risk, and a proportionate program built in the right order will hold up. If you're unsure where your firm sits — captured or not, exposed or covered — that uncertainty is itself the thing to resolve first. Talk to a specialist and we'll tell you straight where you stand and what the fastest safe path forward looks like.